We found results for “”
WS-2018-0175
Good to know:
Date: November 8, 2017
In LimeSurvey, versions prior to 2.72.4+171110 are vulnerable against Improper limitation of a pathname to a restricted directory (Path Traversal). An attacker could manipulate this vulnerability to edit file from outside of the template directory using the template editor. The function 'setTemplateConfiguration' at TemplateConfiguration.php are vulnerable.
Language: PHP
Severity Score
Severity Score
Top Fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | LOW |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | LOW |
Availability (A): | NONE |